Page 156 / 193 Scroll up to view Page 151 - 155
156
Appendix A: Configuring Security Settings on Wireless Clients
4. For the “Shared secret” enter the RADIUS Key you provided to the access point
(on the Advanced >Security page). Retype the key to confirm.
• IP address for the access point.
Click
Next
.
Page 157 / 193
157
Appendix A: Configuring Security Settings on Wireless Clients
5. Click
Finish
.
The access point is now displayed as a client of the Authentication Server.
Page 158 / 193
158
Appendix A: Configuring Security Settings on Wireless Clients
Obtaining a TLS-EAP Certificate for a Client
I
f you want to use IEEE 802.1x mode with EAP-TLS certificates for authentication and
authorization of clients, you must have an external RADIUS server and a
Public Key Authority
Infrastructure
(PKI), including a
Certificate Authority
(CA), server configured on your network.
It is beyond the scope of this document to describe these configuration of the RADIUS server,
PKI, and CA server. Consult the documentation for those products.
Some good starting points available on the Web for the Microsoft Windows PKI software are:
“How to Install/Uninstall a Public Key Certificate Authority for Windows 2000” at
and How to Configure a
Certificate Server at
.
Wireless clients configured to use either “WPA with RADIUS” or” IEEE 802.1x”
security modes with an external RADIUS server that supports TLS-EAP certificates
must obtain a TLS certificate from the RADIUS server.
This is an initial onetime step that must be completed on each client that uses either
of these modes with certificates. In this procedure, we use the Microsoft Certificate
Server as an example.
To obtain a certificate for a client, follow these steps.
1. Go to the following URL in a Web browser:
https://
IPAddressOfServer
/certsrv/
Where
IPAddressOfServer
is the IP address of your external RADIUS
server, or of the
Certificate Authority
(CA), depending on the configuration of your
infrastructure.
2. Click “Yes” to proceed to the secure Web page for the server.
Page 159 / 193
159
Appendix A: Configuring Security Settings on Wireless Clients
The Welcome screen for the Certificate Server is displayed in the browser.
3. Click “Request a certificate” to get the login prompt for the RADIUS server.
4. Provide a valid user name and password to access the RADIUS server.
The user name and password you need to
provide here is for access to the RADIUS
server, for which you will already have
user accounts configured at this point. This
document does not describe how to set up
Administrative user accounts on the RADIUS
server. Please consult the documentation for
your RADIUS server for these procedures.
5. Click “User Certificate” on the next page displayed.
Page 160 / 193
160
Appendix A: Configuring Security Settings on Wireless Clients
6. Click “Yes” on the dialog displayed to install the certificate.
7. Click “Submit” to complete and click “Yes” to confirm the submittal on the popup
dialog.

Rate

4.5 / 5 based on 2 votes.

Bookmark Our Site

Press Ctrl + D to add this site to your favorites!

Share
Top